CREAMSICLE is a backdoor trojan first documented by ZScaler's ThreatLabz in July 2024, associated with the FIN7 (aka Carbon Spider) cybercrime group, and is written in Rust to evade signature-based detection.
CREAMSICLE uses a bespoke C2 protocol over HTTPS to receive encrypted commands, employs an XOR-based encryption for network traffic, and incorporates a custom shellcode loader to execute payloads directly in memory without writing to disk. It achieves persistence via a scheduled task that runs at system startup and performs anti‑analysis checks by enumerating running processes for sandbox tools (e.g., Wireshark, Process Hacker). The malware propagates through spear‑phishing emails containing weaponized LNK files that download the trojan from attacker‑controlled infrastructure. It also leverages living‑off‑the‑land binaries like rundll32.exe to load its DLL component, and can tunnel SOCKS traffic to lateral movement targets.
First reported in July 2024 by ZScaler (report: “FIN7 Resurfaces with New Rust‑Based Malware”), CREAMSICLE was observed in a targeted campaign against U.S. restaurants and hospitality firms. No CVEs are directly associated with the malware itself, but it exploits the CVE‑2023‑36025 flaw in Windows Defender SmartScreen (now patched) to bypass Mark‑of‑the‑Web warnings during initial access. No law enforcement actions have been publicly linked to CREAMSICLE as of early 2025.
Network indicators include HTTP POST requests to C2 domains with a unique User‑Agent string of “Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0” followed by a base64‑encoded beacon. File hashes observed include SHA256 84a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0 (variant sample, per VirusTotal). Registry persistence is set under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a value name “WindowsUpdateHelper”.
The malware allows full remote control of the infected host, enabling data exfiltration of payment card data and personally identifiable information. The primary sector targeted is the U.S. hospitality industry, with financial losses per incident estimated by ZScaler at upwards of $500,000 from credential theft and subsequent point‑of‑sale compromise.
Defenders should enable Windows Defender Attack Surface Reduction rules to block Office‑based LNK execution, block the malicious User‑Agent string via network proxies, and apply the March 2024 Patch Tuesday update for CVE‑2023‑36025 to close the SmartScreen bypass vector.
Similar Threats
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.